Last reviewed: 15 September 2026
Home › The Library › The NAIC Data Security Model Law
What the NAIC Data Security Model Law requires of your agent's agency
Buying insurance means handing an agency your Social Security number, financial details, health information, or all three. The NAIC's Insurance Data Security Model Law (#668) is the regulatory answer to what that agency is actually required to do to protect it — a real, checkable set of obligations, not a vague promise in a privacy policy. Whether it applies to the specific agency you're working with depends on your state.
What Model #668 actually is
The NAIC adopted the Insurance Data Security Model Law in 2017, in response to a string of large data breaches at insurers and agencies handling sensitive consumer information. It applies broadly to "licensees" — insurers, agents, brokers, and other entities licensed by a state Department of Insurance — that handle nonpublic personal information, and it's built around a simple idea: an agency's obligation to protect your data should be a specific, auditable set of practices, not a one-line assurance.
What it actually requires
A licensee subject to the model has to develop, implement, and maintain a written information security program sized to its own complexity and the sensitivity of the data it holds — not a one-size-fits-all checklist. Core, specific obligations include: conducting a risk assessment at least annually; implementing safeguards based on what that assessment actually finds; overseeing third-party service providers who get access to your nonpublic information, rather than treating a vendor relationship as someone else's problem; maintaining a written incident-response plan; and, if a cybersecurity event occurs that meets the model's notice threshold, notifying the state insurance commissioner within 72 hours of determining that the event happened — a specific, dated clock, not a "prompt notification when convenient" standard.
A real exemption for small agencies
The model doesn't apply its full written-security-program requirement uniformly: a licensee with fewer than 10 employees, including independent contractors, is exempt from that specific section, and a licensee already compliant with HIPAA's own security rule can generally satisfy Model #668's requirement through that existing compliance rather than building a second, parallel program. A one- or two-person insurance agency is a genuinely different risk profile than a large brokerage handling thousands of files, and the model's exemption reflects that rather than ignoring smaller operations entirely.
Adoption is real but uneven — check your own state
This is a model law, not a federal statute: it only has force in a state that has actually enacted its own version. As of the NAIC's own most recent legislative tracking, roughly half of NAIC member jurisdictions have adopted a version close enough to the current model to count as adopted — meaning whether an agency handling your information is legally required to meet these specific obligations depends on whether your state is one of them, not on the model existing at all. Don't assume adoption; check your own state Department of Insurance's cybersecurity/data-security guidance, or ask the agency directly whether it maintains a written information security program and how it would notify you of a breach.
What this means for you
A confirmed active producer license (see our licensing guide) says nothing about how carefully an agency protects the data you hand over to get that license-holder to sell you anything. If you're asked for a Social Security number, banking details, or health information as part of an application, it's reasonable to ask the agency directly whether it has a written information security program and how it would notify you if your data were ever exposed — a legitimate agency in a state that has adopted Model #668 is already required to have an answer.